50-essential-mcp-servers-reference

Warn

Audited by Snyk on Jun 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill instructs runtime installation and use of remote MCP servers that fetch and execute code (e.g., multiple "npx -y " installs such as "npx -y @modelcontextprotocol/server-github") and registers hosted MCP endpoints that the agent will call at runtime (e.g., https://mcp.supabase.com, https://mcp.stripe.com), so external content is fetched/executed and can perform actions on the agent's behalf.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The document explicitly lists and provides installation/config examples for money-moving and financial APIs: payment gateways (Stripe, PayPal, Plaid, QuickBooks) and trading/blockchain services (Alpaca, CCXT, Polygon, CoinGecko, Base, Solana agent kit, etc.). It includes a Stripe MCP server section with configuration for secret keys and a warning that it is a "money-moving server" and shows test vs live keys, and an Alpaca example with API keys and paper/live mode. These are specific financial integrations (payment gateways, trading APIs, blockchain services) that can be used to execute payments, trades, or other financial operations, so the skill grants direct financial execution capability.

MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

  • Hidden Unicode characters detected (1 type(s) found)

Issues (3)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

W021
MEDIUM

Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 15, 2026, 01:04 AM
Issues
3
Security Audit — snyk — 50-essential-mcp-servers-reference